A recent report by JUMPSEC highlights an active phishing campaign by the North Korean BlueNoroff group, targeting cryptocurrency staff through fake Zoom and Teams meetings. The attack relies on hijacked Telegram accounts to send genuine-looking invites, leading victims to a rogue platform that extracts sensitive information like crypto wallet details.
The phishing kit operates silently, employing AI-generated videos to simulate live interactions and a ClickFix payload to install malware on both Windows and macOS systems. Notably, this campaign leveraged over 60 hostnames and demonstrated sophisticated techniques typical of state-sponsored cyber operations. Users are advised to verify meeting invites through independent channels and scrutinize URLs before engagement.